Guideline
Decision on the list of processing operations for which a DPIA is mandatory (Dutch DPA)
- Date
- Status
- in force
- Body
- Autoriteit Persoonsgegevens (AP)
- Reference
- Staatscourant 2019, nr. 64418
What it is about
Under Article 35(4) GDPR, read with Article 57(1)(k), the Dutch DPA adopted a list of 17 types of processing for which you must carry out a DPIA in advance, such as covert investigation, blacklists, fraud prevention, credit scores, financial situation, genetic data, health data, cooperation partnerships, camera surveillance, employee monitoring, location data, communication data, internet of things, profiling, observing and influencing behaviour and biometric data. Through the consistency mechanism with the EDPB, biometrics was added. The decision was signed on 19 November 2019 and published in the Government Gazette of 27 November 2019. The list is not exhaustive: if your processing is not on it, a DPIA may still be required when the processing is likely to result in a high risk.
What this means in practice
If your processing is on the list, the starting point is that you carry out a DPIA before you begin processing. Each category states which criteria from the EDPB guidelines (WP248 rev.01) the Dutch DPA took into account, which helps you substantiate your assessment. If the processing is not on the list, you assess yourself using the nine criteria of WP248 rev.01 whether a high risk is likely.
The GDPR articles concerned
Source: Autoriteit Persoonsgegevens, documentpagina met Staatscourant PDF (stcrt-2019-64418)checked on 15 September 2026
Summary and practical reading by Praxikon. Not legal advice; the source prevails.
Connections
What connects to this development
Themes where this returns
The counterpart in the other law
Case law
- The Hague District Court cuts DPA fine on police for mobile camera cars without completed DPIA to 30,000 euros
2024-10-08 · status not established, Rechtbank Den Haag
- WhatsApp v EDPB: a binding EDPB dispute resolution decision can be challenged directly before the EU courts
2026-02-10 · final, Hof van Justitie van de EU (Grote kamer), WhatsApp Ireland Ltd tegen Europees Comité voor gegevensbescherming (EDPB)
- Land Hessen: the supervisory authority need not always fine where the organisation already remedied the breach
2024-09-26 · final, Hof van Justitie van de EU (Eerste kamer), TR tegen Land Hessen
Guidelines
- Consultation on the draft list of processing operations for which no DPIA is required (Dutch DPA)
2026-06-24 · under consultation, Autoriteit Persoonsgegevens (AP)
- EDPB Template for Data Protection Impact Assessment
2026-04-14 · under consultation, European Data Protection Board (EDPB)
- Guidelines on Data Protection Impact Assessment (DPIA) and determining whether processing is likely to result in a high risk
2018-05-25 · final, Article 29 Working Party, bekrachtigd door de European Data Protection Board (EDPB)
- Guidelines 03/2026 on web scraping in the context of generative AI
2026-07-07 · under consultation, European Data Protection Board (EDPB)
- Guidelines 02/2025 on processing of personal data through blockchain technologies
2026-07-07 · final, European Data Protection Board (EDPB)
- Dutch DPA (AP) publishes position paper on the Digital Omnibus and the AI Omnibus
2026-01-13 · final, Autoriteit Persoonsgegevens
- Guidelines on Automated individual decision-making and Profiling for the purposes of Regulation 2016/679
2018-05-25 · final, Article 29 Working Party, bekrachtigd door de European Data Protection Board (EDPB)
- EDPB and EDPS adopt Joint Opinion 2/2026 on the Digital Omnibus
2026-02-10 · final, European Data Protection Board en European Data Protection Supervisor
Enforcement and fines
- 150,000 euro fine for ICS for missing DPIA on digital identity checks
2023-12-18 · final, Autoriteit Persoonsgegevens
- Formal warning to the Dutch Minister of Education, Culture and Science not to put the CABR war archive online and searchable
2024-11-26 · final, Autoriteit Persoonsgegevens
Legislation in motion
- Proposal: EU-wide DPIA lists, template and methodology (Articles 35, 57, 64 and 70 GDPR)
2025-11-19 · proposal, Europese Commissie
- Council: Cyprus Presidency tables negotiating mandate, Coreper vote of 26 June 2026 cancelled
2026-06-22 · under negotiation, Raad van de Europese Unie, Antici-groep (vereenvoudiging) en Coreper
- Commission publishes Digital Omnibus proposal COM(2025) 837
2025-11-19 · proposal, Europese Commissie
Analysis6 of 7
- AI DPIA: when it's required + free template (2026)
2026-03-23
- EU AI Act Article 26: deployer obligations explained
2026-03-21
- DPIA vs FRIA: 5 key differences, when you need both, plus a free FRIA template (2026)
2025-08-05
- AI Act regulator inspection: which documents must your organisation be able to show?
2026-07-07
- What is FRIA? Fundamental rights impact assessment explained (EU AI Act)
2026-02-28
- EU AI Act in the public sector: 2025 government guide
2025-06-16